The text below is the legally binding version. Where the headings or summaries we provide differ from the body of an article, the body controls. We've tried to use clear language wherever possible — if any clause confuses you, please contact us before agreeing.
1. Where your data is stored
The Services run on servers rented from Hetzner Online GmbH and located in Germany (European Union). The application, the database and uploaded files are stored there.
Some supporting providers process limited data on our behalf — for example the payment provider, the email delivery service and push notifications. They are listed on the Sub-processors page (/legal/subprocessors).
↑ Back to top2. Encryption in transit
All traffic between your browser or the mobile app and the Services is encrypted with HTTPS (TLS). Plain HTTP requests are redirected to HTTPS.
↑ Back to top3. Passwords and sign-in
Passwords are never stored in readable form: they are hashed with bcrypt. We cannot see your password and we will never ask you for it.
You can sign in with an email and password or with a Google or Facebook account. Team members sign in with their own accounts, created by the business owner. Repeated failed sign-in attempts and other sensitive requests are rate-limited.
↑ Back to top4. Who can see what
Every business is a separate workspace. Its owner and the team members the owner has added can see the workspace's customers, bookings, service items and messages; owners of other businesses cannot.
A customer sees their own bookings, items and messages. A person who holds the tracking link of an item can follow that item and exchange messages about it without an account — treat tracking links like any other private link.
Access for Enterwait staff to production data is limited to the people who operate the Services and is used for support and maintenance.
↑ Back to top5. Deleting your data
You can delete your account or your workspace yourself, from the settings of the application. Deleted accounts and workspaces go offline immediately, can be restored on request for thirty (30) days, and are then anonymised permanently.
A business owner can download the workspace's data (customers, service items, bookings, services and messages) as files at any time before deleting it.
↑ Back to top6. What we do not claim
Enterwait is a young product. We have not been audited for SOC 2, we are not certified under ISO/IEC 27001, and we have not commissioned an independent penetration test. If your organisation requires any of these, please talk to us before you start using the Services.
↑ Back to top7. Reporting a vulnerability
If you believe you have found a security problem in the Services, please write to office@enterwait.com and describe how to reproduce it. We read every report and will tell you what we found. Please give us reasonable time to fix a problem before making it public, and do not access or change other people's data while testing.
↑ Back to top